US Agencies Accuse Six Chinese AI Firms of Distilling US Frontier Models
Summary
A joint release from the NSA, CISA, and FBI accuses DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of conducting industrial-scale distillation against US frontier models since at least late 2024. The agencies say the firms likely acted with Chinese government awareness and targeted variants of Claude, GPT, Gemini, and Grok to shorten development timelines and reduce training costs. The alleged methods include buying or sharing large numbers of fraudulent accounts, sending thousands to millions of coordinated queries through proxies, and using prompt injection or jailbreaks to elicit hidden reasoning and other restricted capabilities. The agencies recommend stronger identity verification, account and network monitoring, detection of abnormal subscription-to-usage patterns, and information sharing among US companies and allied governments. They also propose silently altering suspicious accounts’ responses, reducing reasoning depth, adding noise, or switching them to less capable models without notice. The agencies acknowledge that such defenses could be technically difficult, could be detected by adaptive attackers, and could mistakenly degrade legitimate users’ service, privacy, precision, and business usefulness. The recommendations follow earlier public accusations by OpenAI, Google, and Anthropic involving DeepSeek and Alibaba. The Chinese Foreign Ministry called the US claims groundless and said China’s AI progress reflects scientific and technological self-reliance, while Chinese officials have also alleged that US companies distill Chinese models. The article notes that the accused firms and targeted US companies had not immediately responded, leaving the practicality of the proposed countermeasures unresolved.